Five active contributors and 21 recent commits show the project is being maintained. The package includes release notes and a changelog, but its broad runtime dependency set and absent security policy add integration and oversight costs.
72%
Total Score
100
50
88
67
The package declares 37 runtime dependencies, including many internal modules and framework integrations. That broad dependency surface increases upgrade and compatibility burden for consumers.
The manifest declares GPL-3.0-or-later, while the artifact also contains an Apache-2.0 font license file. The release is licensed, but the differing detected license warrants checking which files each license covers.
Composer is used for builds, but no security-scanning tools are configured. The missing scanning coverage is a transparency gap, though it does not show abandonment.
The repository has no security policy. For a system module with many runtime integrations, the absence of a documented vulnerability-reporting path lowers operational transparency.
The sole workflow has a high-confidence template-injection finding, but it has no untrusted checkout or script-injection count and no broad write permissions. The finding is therefore a workflow-hygiene concern rather than a standalone severe health risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
amplify/cms Version * | — | — |
amplify/erp Version * | — | — |
amplify/sayt Version * | — | — |
doctrine/dbal Version ^3.8.6 | — | — |
laraflow/form Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.